Commit graph

29 commits

Author SHA1 Message Date
Antony Messerli
8cb64ed88f Move autoexec.ipxe to ipxe root and remove secureboot dirs before checksums
After ISO/USB images are generated from the secureboot directories,
move autoexec.ipxe to the ipxe root as a standalone file and remove
the secureboot directories. This means:
- Checksums are generated cleanly with no secureboot-* subdirectory entries
- autoexec.ipxe is checksummed automatically as a regular ipxe/ file
- build_release needs no special handling for secureboot directories
- autoexec.ipxe flows naturally into both githubout (release asset)
  and s3out (CDN) through the existing copy logic
2026-03-15 17:39:57 -05:00
Antony Messerli
029b06d605 Fix checksums file: remove stale secureboot paths, add autoexec.ipxe
The Ansible-generated checksums file references files under
secureboot-x86_64/ and secureboot-arm64/ which are removed from
githubout. Strip those entries and add the standalone autoexec.ipxe
so the checksums file matches the actual release assets.
2026-03-15 17:14:55 -05:00
Antony Messerli
75e895dfa7 Copy autoexec.ipxe to s3out root for CDN serving
Ensure autoexec.ipxe is available at the root of the S3 bucket
(boot.netboot.xyz/{version}/autoexec.ipxe) alongside other boot
files, not only nested under ipxe/secureboot-x86_64/.
2026-03-15 17:05:27 -05:00
Antony Messerli
e2ac06c49c Publish autoexec.ipxe as standalone release asset for Secure Boot
Instead of repackaging the iPXE signed binaries into netboot.xyz
tarballs, publish only the templated autoexec.ipxe boot script as a
release asset. Consumers (e.g. docker-netbootxyz) download the signed
binaries directly from the upstream iPXE release (ipxeboot.tar.gz),
preserving provenance and avoiding checksum mismatches from
repackaging.

The autoexec.ipxe is identical for both x86_64 and ARM64 -- it
contains the netboot.xyz-specific boot_domain, boot_version, and
menu chain logic with DHCP, failsafe menu, and HTTPS/HTTP fallback.
2026-03-15 16:53:48 -05:00
Antony Messerli
9c0f6f9d08 Package Secure Boot binaries as tarballs in release assets
The Secure Boot directories (secureboot-x86_64/, secureboot-arm64/)
produced by generate_disks_secureboot cannot be uploaded directly as
GitHub release assets since releases are flat file lists. Package them
into secureboot-x86_64.tar.gz and secureboot-arm64.tar.gz so they are
included in the release alongside existing boot files.

This enables docker-netbootxyz and other consumers to download the
signed iPXE Secure Boot binaries and autoexec.ipxe directly from
netboot.xyz releases.
2026-03-15 16:28:23 -05:00
Antony Messerli
acc8de4045 Bump version to 3.x series for code signing certificate update
- Update version.txt from 2.0.90 to 3.0.0
- Update boot_version from 2.x to 3.x in defaults/main.yml
- Update hardcoded version references in script/build_release
- Update example in user_overrides.yml
- Add 3.0.0 changelog entry with breaking change notice
- Users with 2.x bootloaders will auto-upgrade to 3.x on boot

IMPORTANT: Updated binaries should be downloaded to pull latest
netboot.xyz with updated code signing certificates embedded for
image signature verification.
2026-01-24 10:23:09 -06:00
Antony Messerli
ebfc9dacf1 Revert "Wrap vars in quotes"
This reverts commit b9b1e40d03.
2022-07-25 00:07:35 -05:00
Antony Messerli
b9b1e40d03 Wrap vars in quotes 2022-07-24 23:01:25 -05:00
Antony Messerli
4f4eb8b26c Consolidate Dockerfiles
Uses ARGs for whether to add production overrides
or not, by default, it uses the default settings
and not the overrides.
2022-06-26 12:36:40 -05:00
Antony Messerli
a9b0e6aaa5 Fix script for recent lint changes 2022-04-16 00:10:14 -05:00
Antony Messerli
2b87ea8d25
Update build_release 2021-09-30 20:05:14 -05:00
Antony Messerli
5526d4c568
Add some debug 2021-09-30 19:22:23 -05:00
Antony Messerli
4c0de9ca53 Adds rolling release deploy
2.x is designated as a rolling release but usually is aligned
with an actual release.  This commit will allow for updates
to endpoints.yml and the Ansible defaults that contains all
of the version updates to be pushed to boot.netboot.xyz
automatically as they are come in.

This will allow version updates like ArchLinux to be rolled out
immediately with out the lag during releases.
2021-09-30 16:57:08 -05:00
Antony Messerli
d378285372 Remove tty from docker for actions workflow
Hotfix to release to build
2020-12-09 01:43:44 -06:00
Antony Messerli
3830da6bb2 Switch to using Github Actions
With the recent changes to Travis CI, it seemed
like a good time to begin porting netboot.xyz CI
over to Github Actions to keep everything in on
place.  These are the changes for the main
netboot.xyz repo.
2020-12-06 12:00:14 -06:00
Antony Messerli
36eb55b9f0 More tuning for endpoints menu 2020-01-10 01:10:01 -06:00
Antony Messerli
b0144221e1 Set boot_version first before using 2020-01-09 23:39:14 -06:00
Antony Messerli
eb3a703c0e Adds netboot.xyz endpoints menu for testing
Uploads version.ipxe to root of endpoints so that latest
deployed version can be loaded.

Removes memdisk iso test from efi utils menu.
2020-01-09 22:21:34 -06:00
thelamer
274a6ddef8 add if to push a tarball of menu files to S3 for consumption 2019-12-26 09:46:59 -08:00
Antony Messerli
35ee4ce2b5 Set up prod urls
Adjusts variables for production deployment
2019-12-20 15:48:23 +00:00
Antony Messerli
f628157e43 Fixing signatures and add certs to loaders
* Shifting after_deploy messages and aws invalidation to
  proper locations
* Add cert checkout to preinstall and setting those on s3
  deploys only
* Adding production docker file which runs netboot.xyz overrides
* Only display sig menus if enabled
* Fix var names for signing
2019-12-15 22:02:19 +00:00
thelamer
78eac80448 only run the update logic on the rolling .x series, tag the versioned builds to display in menu 2019-12-11 16:45:13 -08:00
thelamer
d6e7be819e tweek ednpoint and update releases to no longer push static html file 2019-12-07 16:35:15 -08:00
Antony Messerli
680965720e Add dosfstools for efi usb build and set -e
Sets -e to exit on failure
2019-11-27 15:27:44 +00:00
Antony Messerli
bf4bcafabd Drop index.html, use from ansible role 2019-11-25 05:52:07 +00:00
Antony Messerli
132399730c Pushing up more changes 2019-11-25 03:37:44 +00:00
Antony Messerli
8c0d988b4d Tuning some settings 2019-11-23 13:34:51 -06:00
thelamer
bc8bf983f5 adding build logic pointed at netboot us-east buckets, semi loop tested 2019-11-18 21:53:06 -08:00
thelamer
3d44646175 testing de push logic in travis other logic still incomplete 2019-11-18 18:28:31 -08:00